Privacy Policy & KVKK Disclosure Notice
Effective & Last Updated: August 17, 2026
1. Data Controller Identity & Contact Details
In accordance with Data Protection Regulations (KVKK & GDPR), your personal data submitted to the Google Business Profile Visibility Audit SaaS platform is processed by the Data Controller.
Data Controller Contact Email: [email protected]
Privacy Rights Request Channel: [email protected]
2. Information We Collect
When requesting a diagnostic audit via our platform, the following data categories are collected:
- Mandatory Identity & Contact Data: Full name, email address.
- Audit Target Profile Data: Google Business Profile Maps URL.
- Optional Business Contact Data: Phone number, company/clinic name, website URL.
- Report & Technical Transaction Logs: Generated audit results, category scores, anonymized IP hash, user agent, and timestamp logs.
3. Purposes of Data Processing
Your personal data is processed strictly for the following purposes:
- Generating, scoring, and delivering your 9-category Google Business Profile visibility audit report.
- Delivering the requested audit report to your email address and providing PDF downloads.
- Providing secure public token report viewing and data verification.
- Marketing & Consultation Communications (Only If Explicit Consent Given): Marketing communications and consultation follow-ups are strictly limited to users who explicitly select the optional marketing consent checkbox. Requesting an audit does NOT automatically subscribe you to marketing emails.
4. Legal Bases for Processing
Data processing is based on GDPR Art. 6(1)(b) / KVKK Art. 5(2)(c) (Performance of a contract/audit delivery), Legitimate Interest for security, and Explicit Consent for optional marketing communications.
5. Google Places API & Public Business Data
Our engine queries official Google Places API (New) endpoints to fetch publicly available business name, address, coordinates, ratings, review counts, and operating hours. This represents public business directory data.
6. Third-Party Service Provider Categories
Your data is handled exclusively through the following verified infrastructure providers:
- Supabase: Encrypted relational database storage.
- Vercel Inc.: Application hosting and serverless edge execution.
- Resend Technologies: Transactional email delivery service.
- Cloudflare Inc.: Turnstile security and bot protection check.
Your personal data is never sold or traded to third parties.
7. International Data Storage & Transfers
Hosting and database infrastructure (Vercel & Supabase) utilize EU and US cloud data centers compliant with SOC 2 and ISO 27001 security standards.
8. Data Retention & Erasure Periods
Submitted lead details and audit reports are retained until explicit erasure requested by the user. Upon 2-step verification via /data-deletion, all live database records are instantly deleted. Backup residuals are purged within a maximum of 30 days.
9. User Rights under Data Protection Laws (KVKK / GDPR)
You have the right to:
- Obtain confirmation as to whether your personal data is being processed,
- Request access to your processed data,
- Learn the purpose of processing,
- Request rectification or complete erasure of your data,
- Object to automated processing outcomes.
10. Privacy Contact Channel
For privacy inquiries, rights requests, or data deletion assistance, please contact us at [email protected]. Requests are answered within 30 days.